From nobody Sat Apr 27 07:25:22 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) client-ip=209.132.183.28; envelope-from=libvir-list-bounces@redhat.com; helo=mx1.redhat.com; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com Return-Path: Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) by mx.zohomail.com with SMTPS id 1516545750584611.3788768744573; Sun, 21 Jan 2018 06:42:30 -0800 (PST) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 40ED44E8B8; Sun, 21 Jan 2018 14:42:28 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.21]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 26CDD60841; Sun, 21 Jan 2018 14:42:26 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 3E9FD4ED34; Sun, 21 Jan 2018 14:42:22 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx04.intmail.prod.int.phx2.redhat.com [10.5.11.14]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id w0LEgJHp013657 for ; Sun, 21 Jan 2018 09:42:20 -0500 Received: by smtp.corp.redhat.com (Postfix) id 5E9815D9C9; Sun, 21 Jan 2018 14:42:19 +0000 (UTC) Received: from mx1.redhat.com (ext-mx10.extmail.prod.ext.phx2.redhat.com [10.5.110.39]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 578C05D9C7 for ; Sun, 21 Jan 2018 14:42:16 +0000 (UTC) Received: from m15-111.126.com (m15-111.126.com [220.181.15.111]) by mx1.redhat.com (Postfix) with ESMTP id 1931D5D676 for ; Sun, 21 Jan 2018 14:42:06 +0000 (UTC) Received: from localhost.localdomain (unknown [58.213.111.46]) by smtp1 (Coremail) with SMTP id C8mowACHxw+spmRaMqhmBA--.50022S2; Sun, 21 Jan 2018 22:41:54 +0800 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=126.com; s=s110527; h=From:Subject:Date:Message-Id; bh=6Hzwv1E2nsk3KEque+ fvpUqhY6NO3iTNP3jB1RjJTSY=; b=Z1MKHNBXqDpoCYcMoySq39uoETLUOWdAgs ocOWjZ31ZC7Nq1sC1cpgcRN91Owi+SLekgciI71OWvrPE6h2i7BS9JnDrBn86pc/ MfQ+A1m9qqcRp4ybSnmjhdgdUht873iBa+aVn4/UZ81q5PGK+btVplHjwP7UKMDX Qrjxk9+uA= From: Chen Hanxiao To: libvir-list@redhat.com Date: Sun, 21 Jan 2018 22:39:34 +0800 Message-Id: <20180121143934.18608-1-chen_han_xiao@126.com> X-CM-TRANSID: C8mowACHxw+spmRaMqhmBA--.50022S2 X-Coremail-Antispam: 1Uf129KBjvJXoW7Kr17CrW7WFWDZryUtr4xWFg_yoW8JF4fp3 9Ikw1Fvr97Jw1xJF90ya48Gry5GFs3KrWjgrs2q34IqrnxCF1093yakFWF9w47CrZ5C3WF qFyYyF9xu34Y9w7anT9S1TB71UUUUUUqnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDUYxBIdaVFxhVjvjDU0xZFpf9x07jUZ2-UUUUU= X-Originating-IP: [58.213.111.46] X-CM-SenderInfo: xfkh0spkdqs5xldrqiyswou0bp/1tbitRLUrlpD4rRd8QAAs+ X-Greylist: Sender passed SPF test, ACL 227 matched, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Sun, 21 Jan 2018 14:42:15 +0000 (UTC) X-Greylist: inspected by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Sun, 21 Jan 2018 14:42:15 +0000 (UTC) for IP:'220.181.15.111' DOMAIN:'m15-111.126.com' HELO:'m15-111.126.com' FROM:'chen_han_xiao@126.com' RCPT:'' X-RedHat-Spam-Score: 1.99 * (DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, FREEMAIL_FROM, RCVD_IN_PSBL, SPF_PASS, T_RP_MATCHES_RCVD) 220.181.15.111 m15-111.126.com 220.181.15.111 m15-111.126.com X-Scanned-By: MIMEDefang 2.78 on 10.5.110.39 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.14 X-loop: libvir-list@redhat.com Cc: Chen Hanxiao Subject: [libvirt] [PATCH v3] libvirtd: clarify the TLS conf default value setting X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.38]); Sun, 21 Jan 2018 14:42:29 +0000 (UTC) X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Content-Type: text/plain; charset="utf-8" From: Chen Hanxiao Provide more details related to the requirement that setting one of the values requires setting all of them. Signed-off-by: Chen Hanxiao Reviewed-by: John Ferlan --- v3: description updated follow John's comments v2: fix a typo daemon/libvirtd.conf | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/daemon/libvirtd.conf b/daemon/libvirtd.conf index 8e0c0d96d..91b3f47de 100644 --- a/daemon/libvirtd.conf +++ b/daemon/libvirtd.conf @@ -182,6 +182,20 @@ # TLS x509 certificate configuration # =20 +# Use of TLS requires that x509 certificates be issued. The default locati= ons +# for the certificate files is as follows: +# +# /etc/pki/CA/cacert.pem - The CA master certificate +# /etc/pki/libvirt/servercert.pem - The server certificate signed= with +# the cacert.pem +# /etc/pki/libvirt/private/serverkey.pem - The server private key +# +# It is possible to override the default locations by altering the 'key_fi= le', +# 'cert_file', and 'ca_file' values and uncommenting them below. +# +# NB, overriding the default of one location requires uncommenting and +# possibly additionally overriding the other settings. +# =20 # Override the default server key file path # --=20 2.14.3 -- libvir-list mailing list libvir-list@redhat.com https://www.redhat.com/mailman/listinfo/libvir-list